In a geographically dispersed deployment of Splunk, where some links are bandwidth constrained, there is need to limit the bandwidth utilized by Spunk to forward events.
In this regard, are there ways to:
1) Limit the bandwidth of a forwarder to a specific value?
2) Configure the forwarder to store events locally from say 9am to 4pm (the peak business hours) and forward outside those hours?
Based on documentation I understand LWF is constrained to 256 kbps. Is this configurable and can the same be done for regular forwarders?
Its possible on LWF, not sure if its works on normal FW's, I asked this question as well in a tech session and it should work as well on FW;s but didnt tried it....
copy SPLUNK_HOME/etc/apps/SplunkLightForwarder/default/limits.conf to SPLUNK_HOME/etc/apps/SplunkLightForwarder/local
and change the settings in
I dont know if you can jobbing the event store question,,,,doubt it but looks meanfulll for me as well!